Results 1 to 4 of 4

Thread: Vulnerability Scan - BEAST Attack

  1. #1
    myarmush is offline Member
    Join Date
    Jul 2012
    Location
    NJ
    Posts
    10
    Rep Power
    1

    Default Vulnerability Scan - BEAST Attack

    A vulnerability scan was run against our Zimbra server and it showed that we were vulnerable to BEAST attack.

    On other servers (Apache/OpenSSL) I am able to mitigate this by setting the cipher order. On Zimbra, I can set the cipher suite but I haven't found any documentation on how to set the order.

    Can this be done? If not, how can BEAST be mitigated for Zimbra?

    Regards,
    Moe
    Release 7.2.2_GA_2852.RHEL6_64_20121204211952 RHEL6_64 NETWORK edition.

  2. #2
    LMStone's Avatar
    LMStone is offline Moderator
    Join Date
    Sep 2006
    Location
    477 Congress Street | Portland, ME 04101
    Posts
    1,281
    Rep Power
    9

    Default

    There is at least one other thread here in the forums which describes restricting the ciphers Zimbra accepts; to my recollection the thread is more than a year old and covers a previous version of Zimbra.

    Hope that helps,
    Mark
    ___________________________________
    L. Mark Stone, Managing Member


    "Uptime. All the time."®

    Ten Years In Business! 2003 - 2013!

    477 Congress Street, Suite 812 | Portland, ME 04101 | (207) 772-5678

    proactive maintenance and monitoring | technology consulting
    Zimbra groupware | cloud hosting | business continuity

    Maine's only managed services and cloud hosting provider with a
    SOC 2 Type II audit covering Security, Availability and Confidentiality

  3. #3
    phoenix is online now Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    21,878
    Rep Power
    51

    Default

    Quote Originally Posted by LMStone View Post
    There is at least one other thread here in the forums which describes restricting the ciphers Zimbra accepts; to my recollection the thread is more than a year old and covers a previous version of Zimbra.
    There's even a wiki article on the subject.
    Regards


    Bill

  4. #4
    myarmush is offline Member
    Join Date
    Jul 2012
    Location
    NJ
    Posts
    10
    Rep Power
    1

    Default

    Thanks for the input guys.

    I have already restricted the cipher suites that Zimbra accepts by using zmprov mcf +zimbraSSLExcludeCipherSuites xxxxx and I set the SSL/TLS settings in Postfix by following the Wiki article at Postfix PCI Compliance in ZCS - Zimbra :: Wiki.

    In other technologies, e.g. Apache Http, I can set the order of the cipher suites without totally excluding them.
    This effectively mitigates BEAST, i.e. an SSL scan from ssllabs.com shows that my web server is not vulnerable to BEAST.

    My question is: can I set the "order" of the ciphers suites without restricting them entirely?

    Regards,
    Moe
    Release 7.2.2_GA_2852.RHEL6_64_20121204211952 RHEL6_64 NETWORK edition.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. SSL certificate related vulnerability
    By k_k in forum Administrators
    Replies: 3
    Last Post: 04-11-2011, 06:30 AM
  2. Vulnerability check for zcs 6.0.6.1
    By chandu in forum Administrators
    Replies: 1
    Last Post: 06-11-2010, 03:57 AM
  3. Spamassassin vulnerability
    By iway in forum Administrators
    Replies: 1
    Last Post: 03-17-2010, 04:55 PM
  4. vulnerability issue
    By chandu in forum Administrators
    Replies: 9
    Last Post: 02-23-2009, 04:04 AM
  5. -=ClamAV Vulnerability=-
    By SpEnTBoY in forum Administrators
    Replies: 0
    Last Post: 06-04-2007, 08:07 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •